CRITICAL KEV
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
Published Mar 26, 2019 ·Due Apr 15, 2022
9.8
CRITICALCVSS 3.1
EPSS 95.07%
Description
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://packetstormsecurity.com/files/157588/Kentico-CMS-12.0.14-Remote-Command-Execution.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://devnet.kentico.com/download/hotfixes#securityBugs-v12 x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2129 Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-10068 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/157588/Kentico-CMS-12.0.14-Remote-Command-Execution.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://devnet.kentico.com/download/hotfixes#securityBugs-v12 | x_refsource_MISCRelease NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2129 | Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-10068 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 26, 2019
Updated Oct 21, 2025
Reserved Mar 26, 2019
Link CVE-2019-10068
CISA Vulnrichment
Updated Feb 7, 2025
Red Hat
No data
ENISA EUVD
Assigner mitre
Published Mar 26, 2019
Updated Oct 21, 2025
Exploited since Mar 25, 2022
Link EUVD-2019-2129
GitHub
No data